mirror of
https://github.com/OpenAMP/open-amp.git
synced 2026-10-02 18:23:21 +08:00
_read() converts the peer-provided unsigned data length to a signed integer and bounds it only against the caller's buffer size. Large values can bypass that comparison or make memcpy() read beyond the fixed response buffer. Reject nonpositive destination sizes, retain the peer length as an unsigned value, and clamp it to both the response payload capacity and the caller's buffer before copying. Signed-off-by: Ben Levinsky <ben.levinsky@amd.com> Assisted-by: Codex:GPT-5